This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

sirefef.AO/AB/AN/AG and blacoleref.BV infections [Solved]

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I went on the government website to check my computer to see if I would lose internet access and soon after I found that MS Security Essentials was off. I uninstalled it and reinstalled it and now it is detecting these trojans… I am running XP on my computer…… Please help!
Hi and welcome,

OTL
  • Download OTL to your desktop.
  • Right-click and Run as Administrator on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under the Custom Scan box paste this in

    netsvcs
    /md5start
    consrv.dll
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT

  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
———-

Please download aswMBR to your desktop.

  • Double click the aswMBR icon to run it.
  • Click the Scan button to start scan.
  • If asked whether you would like to update the Avast virus database please do.
  • When it finishes, press the save log button, save the logfile to your desktop and post its contents in your next reply.

[external image: Posted Image]
Click the image to enlarge it
———-

In your next reply please post the logs made by OTL and aswMBR. :)
Hi, Thanks for helping me out!

Here are the logs created by OTL and aswMBR:

OTL logfile created on: 7/17/2012 6:56:05 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Kevin\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.09 Mb Total Physical Memory | 606.65 Mb Available Physical Memory | 59.35% Memory free
2.40 Gb Paging File | 1.92 Gb Available in Paging File | 80.04% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 37.27 Gb Free Space | 53.40% Space Free | Partition Type: NTFS

Computer Name: D9MDH191 | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Kevin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Sony\Content Manager Assistant\CMAWatcher.exe (Sony Computer Entertainment Inc.)
PRC - C:\Program Files\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.)
PRC - C:\Program Files\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\ooVoo\ooVoo.exe (ooVoo LLC)
PRC - C:\Program Files\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\WINDOWS\system32\scrnsave.scr (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (InstallShield Software Corporation)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\msjetoledb40.dll ()
MOD - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmgit.dll ()
MOD - C:\Program Files\Dell\ShareDLL\djbsdk.dll ()


========== Win32 Services (SafeList) ==========

SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (IAANTMon) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (wanatw) WAN Miniport (ATW) – system32\DRIVERS\wanatw4.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (bvrp_pci) – File not found
DRV - (ctxusbm) – C:\WINDOWS\system32\drivers\ctxusbm.sys (Citrix Systems, Inc.)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell4me.com/myway
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell4me.com/myway
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-2843575100-1658711411-520792388-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKU\S-1-5-21-2843575100-1658711411-520792388-1005\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-21-2843575100-1658711411-520792388-1005\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2843575100-1658711411-520792388-1005\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-2843575100-1658711411-520792388-1005\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-2843575100-1658711411-520792388-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKU\S-1-5-21-2843575100-1658711411-520792388-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
IE - HKU\S-1-5-21-2843575100-1658711411-520792388-1007\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
IE - HKU\S-1-5-21-2843575100-1658711411-520792388-1007\..\URLSearchHook: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - No CLSID value found
IE - HKU\S-1-5-21-2843575100-1658711411-520792388-1007\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-2843575100-1658711411-520792388-1007\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKU\S-1-5-21-2843575100-1658711411-520792388-1007\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yankees.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/06/16 13:00:48 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/12 06:35:36 | 000,000,000 | —D | M]

[2010/10/02 23:02:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Extensions
[2012/07/15 00:39:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\mvuvldgi.default\extensions
[2011/08/25 07:11:00 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\mvuvldgi.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2010/10/06 05:18:18 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\mvuvldgi.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/03/14 23:38:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/06/16 13:00:47 | 000,085,472 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/03/11 00:01:02 | 000,124,272 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\CCMSDK.dll
[2010/03/11 00:02:52 | 000,070,512 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\CgpCore.dll
[2010/03/11 00:01:48 | 000,091,504 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\confmgr.dll
[2010/03/11 00:01:24 | 000,022,384 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\ctxlogging.dll
[2012/02/19 08:07:42 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/10/02 22:59:55 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2010/03/11 00:40:56 | 000,423,248 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npicaN.dll
[2010/03/11 00:02:48 | 000,023,920 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\TcpPServ.dll
[2011/12/16 21:20:10 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/16 21:20:10 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/10 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKU\.DEFAULT..\Run: [Apple] C:\Documents and Settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll (Microsoft Corporation)
O4 - HKU\S-1-5-18..\Run: [Apple] C:\Documents and Settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [Apple] C:\Documents and Settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Apple] C:\Documents and Settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-2843575100-1658711411-520792388-1005..\Run: [Apple] C:\Documents and Settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-2843575100-1658711411-520792388-1005..\Run: [ooVoo.exe] C:\Program Files\ooVoo\oovoo.exe (ooVoo LLC)
O4 - HKU\S-1-5-21-2843575100-1658711411-520792388-1007..\Run: [Apple] C:\Documents and Settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Content Manager Assistant for PlayStation®.lnk = C:\Program Files\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2843575100-1658711411-520792388-1005\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-2843575100-1658711411-520792388-1007\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{77523D75-4D69-4744-A6F6-835953D76D1B}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Kevin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kevin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 06:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\{7ff91535-daff-11df-893d-00123f7dd9e0}\Shell - "" = AutoRun
O33 - MountPoints2\{7ff91535-daff-11df-893d-00123f7dd9e0}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{7ff91535-daff-11df-893d-00123f7dd9e0}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{c6392ec8-e559-11df-894b-00123f7dd9e0}\Shell - "" = AutoRun
O33 - MountPoints2\{c6392ec8-e559-11df-894b-00123f7dd9e0}\Shell\AutoRun - "" = Auto&Play;
O33 - MountPoints2\{c6392ec8-e559-11df-894b-00123f7dd9e0}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: 6to4 - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Sharedaccess - File not found
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/17 18:43:00 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kevin\Desktop\OTL.exe
[2012/07/08 18:07:47 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client
[39 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/17 18:53:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/07/17 18:43:05 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kevin\Desktop\OTL.exe
[2012/07/15 02:03:57 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/07/14 20:47:04 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/07/14 02:47:03 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/07/11 03:19:52 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/07/11 03:19:49 | 1071,812,608 | -HS- | M] () – C:\hiberfil.sys
[2012/07/11 03:19:49 | 000,187,408 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/07/08 18:08:17 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2012/07/08 18:07:35 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[39 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/08 18:18:00 | 000,000,384 | -H– | C] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/07/08 18:08:01 | 000,001,698 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/07/08 14:47:58 | 000,000,804 | —- | C] () – C:\WINDOWS\Installer\{7d319631-b6db-4b10-7bca-e218d5c0154c}\L\00000004.@
[2012/02/16 00:12:12 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/05/09 06:41:23 | 000,000,558 | —- | C] () – C:\WINDOWS\hpomdl37.dat.temp
[2010/12/14 19:36:22 | 000,013,312 | —- | C] () – C:\Documents and Settings\Kevin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/03 19:22:33 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\E9DA6A2B40.sys
[2010/10/03 19:22:00 | 000,061,678 | —- | C] () – C:\Documents and Settings\Kevin\Application Data\PFP120JPR.{PB
[2010/10/03 19:22:00 | 000,012,358 | —- | C] () – C:\Documents and Settings\Kevin\Application Data\PFP120JCM.{PB
[2010/10/03 10:58:23 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/10/02 23:36:35 | 000,135,167 | —- | C] () – C:\WINDOWS\hpoins37.dat
[2010/10/02 23:36:35 | 000,000,558 | —- | C] () – C:\WINDOWS\hpomdl37.dat
[2010/10/02 12:33:15 | 000,004,184 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2010/10/02 12:20:00 | 000,000,136 | —- | C] () – C:\Documents and Settings\Kevin\Local Settings\Application Data\fusioncache.dat
[2010/10/01 18:05:19 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005/08/16 06:18:29 | 000,002,048 | -HS- | C] () – C:\WINDOWS\Installer\{7d319631-b6db-4b10-7bca-e218d5c0154c}\@
[2005/08/16 06:18:29 | 000,002,048 | -HS- | C] () – C:\Documents and Settings\Kevin\Local Settings\Application Data\{7d319631-b6db-4b10-7bca-e218d5c0154c}\@

========== LOP Check ==========

[2010/10/20 18:00:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2005/08/16 22:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2011/01/05 23:30:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Garmin
[2012/02/07 19:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2012/03/24 08:42:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\GARMIN
[2010/10/21 07:26:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\ICAClient
[2010/12/05 12:09:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\Leadertech
[2010/10/02 23:00:06 | 000,000,000 | —D | M] – C:\Documents and Settings\Missy\Application Data\Foxit Software
[2011/08/17 19:38:53 | 000,000,000 | —D | M] – C:\Documents and Settings\Missy\Application Data\GARMIN
[2010/10/20 18:05:24 | 000,000,000 | —D | M] – C:\Documents and Settings\Missy\Application Data\ICAClient
[2010/11/04 20:36:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Missy\Application Data\Leadertech
[2011/11/07 20:06:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Missy\Application Data\ooVoo Details
[2011/02/03 16:49:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Whitney\Application Data\ICAClient

========== Purity Check ==========



========== Custom Scans ==========

< MD5 for: EXPLORER.EXE >
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\explorer.exe
[2008/04/14 05:42:20 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINDOWS\ServicePackFiles\i386\explorer.exe
[2004/08/10 07:00:00 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINDOWS\$NtServicePackUninstall$\explorer.exe

< MD5 for: SVCHOST.EXE >
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\i386\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\ServicePackFiles\i386\svchost.exe
[2008/04/14 05:42:38 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=27C6D03BCDB8CFEB96B716F3D8BE3E18 – C:\WINDOWS\system32\svchost.exe
[2004/08/10 07:00:00 | 000,014,336 | —- | M] (Microsoft Corporation) MD5=8F078AE4ED187AAABC0A305146DE6716 – C:\WINDOWS\$NtServicePackUninstall$\svchost.exe

< MD5 for: USERINIT.EXE >
[2004/08/10 07:00:00 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\i386\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/14 05:42:40 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\system32\userinit.exe

< MD5 for: WINLOGON.EXE >
[2004/08/10 07:00:00 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\i386\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/14 05:42:40 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\system32\winlogon.exe

< End of report >

********************************************************************************
*********************************************************************************
**********

OTL Extras logfile created on: 7/17/2012 6:56:05 PM - Run 1
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Kevin\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.09 Mb Total Physical Memory | 606.65 Mb Available Physical Memory | 59.35% Memory free
2.40 Gb Paging File | 1.92 Gb Available in Paging File | 80.04% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 37.27 Gb Free Space | 53.40% Space Free | Partition Type: NTFS

Computer Name: D9MDH191 | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

[HKEY_USERS\S-1-5-21-2843575100-1658711411-520792388-1005\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

[HKEY_USERS\S-1-5-21-2843575100-1658711411-520792388-1007\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with FastStone] – "C:\Program Files\FastStone Image Viewer\FSViewer.exe" "%1" ()
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{023D64D7-E7B4-47C7-BE6E-B7C2E8960D08}" = Citrix online plug-in (Web)
"{0456ebd7-5f67-4ab6-852e-63781e3f389c}" = Macromedia Flash Player
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{075473F5-846A-448B-BCB3-104AA1760205}" = Sonic RecordNow Data
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0BEDBD4E-2D34-47B5-9973-57E62B29307C}" = ATI Control Panel
"{0EB5D9B7-8E6C-4A9E-B74F-16B7EE89A67B}" = Microsoft Plus! Photo Story 2 LE
"{0F842B77-56EA-4AAF-8295-81A022350B5E}" = Microsoft Security Client
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{21657574-BD54-48A2-9450-EB03B2C7FC29}" = Sonic MyDVD LE
"{25C65D81-1C50-497D-9246-F17824CCC966}" = Garmin BaseCamp
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{292F0F52-B62D-4E71-921B-89A682402201}" = Toolbox
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Sonic Update Manager
"{33BB4982-DC52-4886-A03B-F4C5C80BEE89}" = Windows Media Player 10
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35BDEFF1-A610-4956-A00D-15453C116395}" = Internet Explorer Default Page
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3F92ABBB-6BBF-11D5-B229-002078017FBF}" = NetWaiting
"{414A373B-59DF-4102-94CA-9FE9A74CBDDA}" = Garmin Trip and Waypoint Manager v5
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CEA6811-DFAD-4892-828D-49941FE3B779}" = Intel® PROSet for Wired Connections
"{548EEA8E-8299-497F-8057-811D2D7097DC}" = Dell Support 3.1
"{5905F42D-3F5F-4916-ADA6-94A3646AEE76}" = Dell Driver Reset Tool
"{62BD0AE0-4EB1-4BBB-8F43-B6400C8FEB2C}" = AOLIcon
"{65F9E1F3-A2C1-4AA9-9F33-A3AEB0255F0E}" = Garmin USB Drivers
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD 5.5
"{6D5FCA42-1486-4E32-AFE8-1B7E2AA59D33}" = Digital Content Portal
"{6E45BA47-383C-4C1E-8ED0-0D4845C293D7}" = Microsoft Plus! Digital Media Edition Installer
"{6F8EAC65-314D-4D86-9557-BC9312AACCB0}" = Citrix online plug-in (USB)
"{7148F0A8-6813-11D6-A77B-00B0D0142030}" = Java 2 Runtime Environment, SE v1.4.2_03
"{74F7662C-B1DB-489E-A8AC-07A06B24978B}" = Dell System Restore
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7BE15435-2D3E-4B58-867F-9C75BED0208C}" = QuickTime
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{8144262B-25B4-44F6-8204-FCC8EF50179F}" = Citrix online plug-in (DV)
"{85D3CC30-8859-481A-9654-FD9B74310BEF}" = Musicmatch® Jukebox
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A9B8148-DDD7-448F-BD6C-358386D32354}" = Corel Photo Album 6
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel Matrix Storage Manager
"{92127AF5-FDD8-4ADF-BC40-C356C9EE0B7D}" = 32 Bit HP CIO Components Installer
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9941F0AA-B903-4AF4-A055-83A9815CC011}" = Sonic Encoders
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A683A2C0-821C-486F-858C-FA634DB5E864}" = EducateU
"{A800FCC9-8E1E-4D84-9CED-47870701FDE1}" = HP Deskjet F4400 Printer Driver 14.0 Rel. 5
"{A83279FD-CA4B-4206-9535-90974DE76654}" = Apple Application Support
"{A835C187-691C-4827-BCEA-1611179C96B9}" = DJ_AIO_05_F4400_Software_Min
"{AB708C9B-97C8-4AC9-899B-DBF226AC9382}" = Sonic RecordNow Audio
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{AF19F291-F22F-4798-9662-525305AE9E48}" = WordPerfect Office 12
"{B1102A25-3AA3-446B-AA0F-A699B07A02FD}" = Garmin USB Drivers
"{B12665F4-4E93-4AB4-B7FC-37053B524629}" = Sonic RecordNow Copy
"{BE841724-78F0-44D6-B6C4-C3D53708293B}" = Content Manager Assistant for PlayStation®
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D2988E9B-C73F-422C-AD4B-A66EBE257120}" = MCU
"{E646DCF0-5A68-11D5-B229-002078017FBF}" = Digital Line Detect
"{E93E5EF6-D361-481E-849D-F16EF5C78EBC}" = Musicmatch for Windows Media Player
"{EA74A293-3FAC-4D1B-AE3A-3BD47FADDC20}" = Citrix online plug-in (HDX)
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"12133444-BF36-4d4e-B7FB-A3424C645DE4" = GemMaster Mystic
"45A7283175C62FAC673F913C1F532C5361F97841" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (03/08/2007 2.2.1.0)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"ATI Display Driver" = ATI Display Driver
"B3EE3001-DC24-4cd1-8743-5692C716659F" = Otto
"CitrixOnlinePluginPackWeb" = Citrix online plug-in - web
"CNXT_MODEM_PCI_VEN_14F1&DEV;_2F20&SUBSYS;_200F14F1" = Conexant D850 56K V.9x DFVc Modem
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"EmeraldQFE2" = Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
"ESPNMotion" = ESPNMotion
"FastStone Image Viewer" = FastStone Image Viewer 4.2
"ie8" = Windows Internet Explorer 8
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"PROSet" = Intel® PRO Network Connections Drivers
"RealPlayer 6.0" = RealPlayer Basic
"StreetPlugin" = Learn2 Player (Uninstall Only)
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/13/2012 6:10:58 PM | Computer Name = D9MDH191 | Source = .NET Runtime Optimization Service | ID = 1103
Description = .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32)
- Tried to start a service that wasn't the latest version of CLR Optimization service.
Will shutdown

Error - 7/8/2012 2:53:12 PM | Computer Name = D9MDH191 | Source = Microsoft Security Client | ID = 5000
Description =

Error - 7/8/2012 2:53:53 PM | Computer Name = D9MDH191 | Source = Microsoft Security Client | ID = 5000
Description =

Error - 7/8/2012 2:54:09 PM | Computer Name = D9MDH191 | Source = Microsoft Security Client | ID = 5000
Description =

Error - 7/8/2012 2:54:11 PM | Computer Name = D9MDH191 | Source = Microsoft Security Client | ID = 5000
Description =

Error - 7/8/2012 2:55:14 PM | Computer Name = D9MDH191 | Source = Microsoft Security Client | ID = 5000
Description =

Error - 7/8/2012 6:07:57 PM | Computer Name = D9MDH191 | Source = MPSampleSubmission | ID = 5000
Description = EventType mptelemetry, P1 0x80070003, P2 moac, P3 cachereset, P4 4.0.1526.0,
P5 unspecified, P6 unspecified, P7 unspecified, P8 NIL, P9 NIL, P10 NIL.

Error - 7/8/2012 6:08:02 PM | Computer Name = D9MDH191 | Source = Microsoft Security Client | ID = 5000
Description =

Error - 7/16/2012 9:06:54 PM | Computer Name = D9MDH191 | Source = Application Hang | ID = 1002
Description = Hanging application msseces.exe, version 4.0.1526.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 7/17/2012 6:50:36 PM | Computer Name = D9MDH191 | Source = Application Hang | ID = 1002
Description = Hanging application OTL.exe, version 3.2.54.0, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 7/8/2012 6:21:27 PM | Computer Name = D9MDH191 | Source = SideBySide | ID = 16842786
Description = Component identity found in manifest does not match the identity of
the component requested

Error - 7/8/2012 6:21:27 PM | Computer Name = D9MDH191 | Source = SideBySide | ID = 16842810
Description = Syntax error in manifest or policy file "C:\Program Files\Citrix\ICA
Client\Microsoft.VC80.MFCLOC.MANIFEST" on line 5.

Error - 7/8/2012 6:21:27 PM | Computer Name = D9MDH191 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Citrix\ICA
Client\MFC80.DLL. Reference error message: The operation completed successfully.
.

Error - 7/8/2012 6:22:53 PM | Computer Name = D9MDH191 | Source = Service Control Manager | ID = 7023
Description = The Computer Browser service terminated with the following error:
%%1060

Error - 7/11/2012 6:24:08 PM | Computer Name = D9MDH191 | Source = SideBySide | ID = 16842786
Description = Component identity found in manifest does not match the identity of
the component requested

Error - 7/11/2012 6:24:08 PM | Computer Name = D9MDH191 | Source = SideBySide | ID = 16842810
Description = Syntax error in manifest or policy file "C:\Program Files\Citrix\ICA
Client\Microsoft.VC80.MFCLOC.MANIFEST" on line 5.

Error - 7/11/2012 6:24:08 PM | Computer Name = D9MDH191 | Source = SideBySide | ID = 16842811
Description = Generate Activation Context failed for C:\Program Files\Citrix\ICA
Client\MFC80.DLL. Reference error message: The operation completed successfully.
.


< End of report >


********************************************************************************
*********************************************************************************
**********

aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-17 19:01:57
—————————–
19:01:57.731 OS Version: Windows 5.1.2600 Service Pack 3
19:01:57.731 Number of processors: 2 586 0x404
19:01:57.731 ComputerName: D9MDH191 UserName: Kevin
19:01:59.638 Initialize success
19:03:56.451 AVAST engine defs: 12071701
19:04:06.576 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0
19:04:06.576 Disk 0 Vendor: Maxtor_6 BACE Size: 76293MB BusType: 3
19:04:06.623 Disk 0 MBR read successfully
19:04:06.623 Disk 0 MBR scan
19:04:06.795 Disk 0 unknown MBR code
19:04:06.795 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 54 MB offset 63
19:04:06.841 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 71468 MB offset 112455
19:04:06.873 Disk 0 Partition 3 00 DB CP/M / CTOS Dell 8.0 4753 MB offset 146496735
19:04:06.888 Disk 0 scanning sectors +156232125
19:04:06.982 Disk 0 scanning C:\WINDOWS\system32\drivers
19:04:32.451 Service scanning
19:04:50.607 Service MpKsl88065a84 c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{78F99DAC-7936-499C-BCDB-D2192640EFDD}\MpKsl88065a84.sys **LOCKED** 32
19:05:09.170 Modules scanning
19:05:15.654 Disk 0 trace - called modules:
19:05:15.670 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll
19:05:15.670 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86f8aab8]
19:05:15.670 3 CLASSPNP.SYS[f7592fd7] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x86f75030]
19:05:16.326 AVAST engine scan C:\WINDOWS
19:05:26.186 AVAST engine scan C:\WINDOWS\system32
19:10:30.156 AVAST engine scan C:\WINDOWS\system32\drivers
19:10:59.282 AVAST engine scan C:\Documents and Settings\Kevin
19:14:51.096 AVAST engine scan C:\Documents and Settings\All Users
19:21:47.036 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Kevin\Desktop\MBR.dat"
19:21:47.051 The log file has been saved successfully to "C:\Documents and Settings\Kevin\Desktop\aswMBR.txt"
Hi,

**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again.

Unfortunately I have found what is known as the ZeroAccess rootkit on your system. It is an especially nasty infection that can take quite some time to clean as well as may have damaged your system files itself. As a warning, during the cleaning (if you choose to do so) you may lose internet access with this computer and in the end we may need to reinstall the operating system anyway depending on the extent of the infection.

If you would like to format and reinstall your Operating System please let me know and we can assist you with that.

If you would like to continue with the cleaning, please continue with the following instructions and I will be more than happy to help. :)
———-

Please download and run ERUNT (Emergency Recovery Utility NT). This program allows you to keep a complete backup of your registry and restore it when needed. The standard registry backup options that come with Windows back up most of the registry but not all of it. ERUNT however creates a complete backup set, including the Security hive and user related sections. ERUNT is easy to use and since it creates a full backup, there are no options or choices other than to select the location of the backup files. The backup set includes a small executable that will launch the registry restore if needed. **Remember if you are using Windows Vista as your operating system right-click the executable and Run as Administrator.
———-

If you are running Malwarebytes 1.6 or better, please disable it for the duration of this run.

To disable Malwarebytes
  • Open the scanner and select the Protection tab
  • Remove the tick from "Start Protection Module with Windows" as seen below
[external image: Posted Image]

Once complete continue with the instructions…
———-

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Files
    C:\WINDOWS\Installer\{7d319631-b6db-4b10-7bca-e218d5c0154c}\
    C:\Documents and Settings\Kevin\Local Settings\Application Data\{7d319631-b6db-4b10-7bca-e218d5c0154c}\
    
    :Commands
    [purity]
    [emptytemp]
    [start explorer]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then run a new scan and post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )
———-

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
4. If you get a message saying "Illegal operation attempted on a registry key that has been marked for deletion", please restart your computer.
———-

Please post the logs made by OTL and ComboFix if you are going to attempt cleaning. :)
Ok, I've changed all important passwords and am ready to proceed….. My girlfriend has a lot of pictures on the computer that she doesn't want to lose… If I format and reinstall my Operating system will she lose all of those? Or can we try cleaning without reformatting the OS? :unsure:
Hi, Sure we can continue with cleaning the system. Even if we can't beat the infection (which we have good results with) we can get your pictures and personal files off. :) If you want to continue with cleaning please perform all the instructions in Post 4.
After I run OTL and RUN FIX and you want me to do a quick scan, should i paste these in Custom Scans/Fixes like i did with the first scan you had me run? netsvcs /md5start consrv.dll explorer.exe winlogon.exe Userinit.exe svchost.exe /md5stop CREATERESTOREPOINT
Okay, here are the two logs requested:


OTL logfile created on: 7/22/2012 6:54:37 AM - Run 2
OTL by OldTimer - Version 3.2.54.0 Folder = C:\Documents and Settings\Kevin\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

1022.09 Mb Total Physical Memory | 406.94 Mb Available Physical Memory | 39.81% Memory free
2.40 Gb Paging File | 1.93 Gb Available in Paging File | 80.21% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 69.79 Gb Total Space | 39.58 Gb Free Space | 56.71% Space Free | Partition Type: NTFS

Computer Name: D9MDH191 | User Name: Kevin | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Kevin\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
PRC - c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
PRC - C:\Program Files\Sony\Content Manager Assistant\CMAWatcher.exe (Sony Computer Entertainment Inc.)
PRC - C:\Program Files\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.)
PRC - C:\Program Files\Citrix\ICA Client\wfcrun32.exe (Citrix Systems, Inc.)
PRC - C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Real\RealPlayer\realplay.exe (RealNetworks, Inc.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe (Musicmatch, Inc.)
PRC - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\MMDiag.exe (Musicmatch, Inc.)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe (InstallShield Software Corporation)
PRC - C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
MOD - C:\WINDOWS\system32\quartz.dll ()
MOD - C:\WINDOWS\system32\sbe.dll ()
MOD - C:\WINDOWS\system32\msdmo.dll ()
MOD - C:\WINDOWS\system32\devenum.dll ()
MOD - C:\WINDOWS\system32\msjetoledb40.dll ()
MOD - C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mmgit.dll ()
MOD - C:\Program Files\Dell\ShareDLL\djbsdk.dll ()


========== Win32 Services (SafeList) ==========

SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (MsMpSvc) – c:\Program Files\Microsoft Security Client\MsMpEng.exe (Microsoft Corporation)
SRV - (IAANTMon) Intel® – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (WDICA) – File not found
DRV - (wanatw) WAN Miniport (ATW) – system32\DRIVERS\wanatw4.sys File not found
DRV - (PDRFRAME) – File not found
DRV - (PDRELI) – File not found
DRV - (PDFRAME) – File not found
DRV - (PDCOMP) – File not found
DRV - (PCIDump) – File not found
DRV - (lbrtfdc) – File not found
DRV - (Changer) – File not found
DRV - (bvrp_pci) – File not found
DRV - (MpKsladdc328d) – c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\MpKsladdc328d.sys (Microsoft Corporation)
DRV - (ctxusbm) – C:\WINDOWS\system32\drivers\ctxusbm.sys (Citrix Systems, Inc.)
DRV - (WDC_SAM) – C:\WINDOWS\system32\drivers\wdcsam.sys (Western Digital Technologies)
DRV - (ASCTRM) – C:\WINDOWS\System32\drivers\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={sea…ferrer:source?}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
IE - HKCU\..\URLSearchHook: {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yankees.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: {195A3098-0BD5-4e90-AE22-BA1C540AFD1E}:2.9.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..network.proxy.type: 0
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32_11_3_300_265.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/07/20 06:44:23 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2012/04/12 06:35:36 | 000,000,000 | —D | M]

[2010/10/02 23:02:36 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Extensions
[2012/07/15 00:39:31 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\mvuvldgi.default\extensions
[2011/08/25 07:11:00 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\mvuvldgi.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2010/10/06 05:18:18 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Kevin\Application Data\Mozilla\Firefox\Profiles\mvuvldgi.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2012/03/14 23:38:28 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2012/07/20 06:44:23 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/03/11 00:01:02 | 000,124,272 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\CCMSDK.dll
[2010/03/11 00:02:52 | 000,070,512 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\CgpCore.dll
[2010/03/11 00:01:48 | 000,091,504 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\confmgr.dll
[2010/03/11 00:01:24 | 000,022,384 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\ctxlogging.dll
[2012/02/19 08:07:42 | 000,476,904 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/10/02 22:59:55 | 000,075,208 | —- | M] (Foxit Software Company) – C:\Program Files\mozilla firefox\plugins\npFoxitReaderPlugin.dll
[2010/03/11 00:40:56 | 000,423,248 | —- | M] () – C:\Program Files\mozilla firefox\plugins\npicaN.dll
[2010/03/11 00:02:48 | 000,023,920 | —- | M] (Citrix Systems, Inc.) – C:\Program Files\mozilla firefox\plugins\TcpPServ.dll
[2011/12/16 21:20:10 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/12/16 21:20:10 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

O1 HOSTS File: ([2004/08/10 07:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ConnectionCenter] C:\Program Files\Citrix\ICA Client\concentr.exe (Citrix Systems, Inc.)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [MimBoot] C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mimboot.exe (Musicmatch, Inc.)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKCU..\Run: [Apple] C:\Documents and Settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Content Manager Assistant for PlayStation®.lnk = C:\Program Files\Sony\Content Manager Assistant\CMA.exe (Sony Computer Entertainment Inc.)
O4 - Startup: C:\Documents and Settings\Kevin\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{77523D75-4D69-4744-A6F6-835953D76D1B}: DhcpNameServer = [removed] [removed]
O18 - Protocol\Filter\application/x-ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O18 - Protocol\Filter\ica {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll (Citrix Systems, Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Kevin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Kevin\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 06:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\{7ff91535-daff-11df-893d-00123f7dd9e0}\Shell - "" = AutoRun
O33 - MountPoints2\{7ff91535-daff-11df-893d-00123f7dd9e0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7ff91535-daff-11df-893d-00123f7dd9e0}\Shell\AutoRun\command - "" = "F:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\{c6392ec8-e559-11df-894b-00123f7dd9e0}\Shell - "" = AutoRun
O33 - MountPoints2\{c6392ec8-e559-11df-894b-00123f7dd9e0}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c6392ec8-e559-11df-894b-00123f7dd9e0}\Shell\AutoRun\command - "" = F:\LaunchU3.exe -a
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/07/21 22:26:39 | 000,000,000 | —D | C] – C:\_OTL
[2012/07/21 22:23:46 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2012/07/21 22:23:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2012/07/21 22:23:10 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2012/07/17 19:01:15 | 004,731,392 | —- | C] (AVAST Software) – C:\Documents and Settings\Kevin\Desktop\aswMBR.exe
[2012/07/17 18:43:00 | 000,596,480 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Kevin\Desktop\OTL.exe
[2012/07/08 18:07:47 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Security Client

========== Files - Modified Within 30 Days ==========

[2012/07/22 06:53:00 | 000,000,830 | —- | M] () – C:\WINDOWS\tasks\Adobe Flash Player Updater.job
[2012/07/22 01:36:33 | 000,000,384 | -H– | M] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/07/21 22:33:26 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2012/07/21 22:33:23 | 1071,812,608 | -HS- | M] () – C:\hiberfil.sys
[2012/07/21 22:23:25 | 000,000,767 | —- | M] () – C:\Documents and Settings\Kevin\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/07/21 20:47:11 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2012/07/21 02:47:01 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2012/07/17 19:21:47 | 000,000,512 | —- | M] () – C:\Documents and Settings\Kevin\Desktop\MBR.dat
[2012/07/17 19:01:35 | 004,731,392 | —- | M] (AVAST Software) – C:\Documents and Settings\Kevin\Desktop\aswMBR.exe
[2012/07/17 18:43:05 | 000,596,480 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Kevin\Desktop\OTL.exe
[2012/07/11 03:19:49 | 000,187,408 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2012/07/08 18:08:17 | 000,001,945 | —- | M] () – C:\WINDOWS\epplauncher.mif
[2012/07/08 18:07:35 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl

========== Files Created - No Company Name ==========

[2012/07/21 22:23:25 | 000,000,767 | —- | C] () – C:\Documents and Settings\Kevin\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2012/07/17 19:21:47 | 000,000,512 | —- | C] () – C:\Documents and Settings\Kevin\Desktop\MBR.dat
[2012/07/08 18:18:00 | 000,000,384 | -H– | C] () – C:\WINDOWS\tasks\Microsoft Antimalware Scheduled Scan.job
[2012/07/08 18:08:01 | 000,001,698 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/02/16 00:12:12 | 000,003,072 | —- | C] () – C:\WINDOWS\System32\iacenc.dll
[2011/05/09 06:41:23 | 000,000,558 | —- | C] () – C:\WINDOWS\hpomdl37.dat.temp
[2010/12/14 19:36:22 | 000,013,312 | —- | C] () – C:\Documents and Settings\Kevin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/03 19:22:33 | 000,000,104 | RHS- | C] () – C:\WINDOWS\System32\E9DA6A2B40.sys
[2010/10/03 19:22:00 | 000,061,678 | —- | C] () – C:\Documents and Settings\Kevin\Application Data\PFP120JPR.{PB
[2010/10/03 19:22:00 | 000,012,358 | —- | C] () – C:\Documents and Settings\Kevin\Application Data\PFP120JCM.{PB
[2010/10/03 10:58:23 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/10/02 23:36:35 | 000,135,167 | —- | C] () – C:\WINDOWS\hpoins37.dat
[2010/10/02 23:36:35 | 000,000,558 | —- | C] () – C:\WINDOWS\hpomdl37.dat
[2010/10/02 12:33:15 | 000,004,184 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2010/10/02 12:20:00 | 000,000,136 | —- | C] () – C:\Documents and Settings\Kevin\Local Settings\Application Data\fusioncache.dat
[2010/10/01 18:05:19 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini

========== LOP Check ==========

[2010/10/20 18:00:20 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Citrix
[2005/08/16 22:54:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\DIGStream
[2011/01/05 23:30:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Garmin
[2012/02/07 19:05:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iolo
[2012/03/24 08:42:28 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\GARMIN
[2010/10/21 07:26:56 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\ICAClient
[2010/12/05 12:09:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Kevin\Application Data\Leadertech

========== Purity Check ==========



< End of report >


********************************************************************************
*************************************



ComboFix 12-07-21.01 - Kevin 07/22/2012 7:12.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.538 [GMT -4:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}
AV: Microsoft Security Essentials *Disabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll
c:\program files\FunWebProducts
c:\windows\system32\_000006_.tmp.dll
c:\windows\system32\_000007_.tmp.dll
c:\windows\system32\_000008_.tmp.dll
c:\windows\system32\_000009_.tmp.dll
c:\windows\system32\_000010_.tmp.dll
c:\windows\system32\_000019_.tmp.dll
c:\windows\system32\_000020_.tmp.dll
c:\windows\system32\_000021_.tmp.dll
c:\windows\system32\_000022_.tmp.dll
.
.
((((((((((((((((((((((((( Files Created from 2012-06-22 to 2012-07-22 )))))))))))))))))))))))))))))))
.
.
2012-07-22 05:38 . 2012-07-22 05:38 56200 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\offreg.dll
2012-07-22 05:38 . 2012-07-22 05:38 29904 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\MpKsladdc328d.sys
2012-07-22 05:37 . 2012-06-29 08:44 6891424 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\mpengine.dll
2012-07-22 02:26 . 2012-07-22 02:26 ——– d—–w- C:\_OTL
2012-07-22 02:23 . 2012-07-22 02:23 ——– d—–w- c:\program files\ERUNT
2012-07-21 19:49 . 2012-06-29 08:44 6891424 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-07-08 22:07 . 2012-07-08 22:08 ——– d—–w- c:\program files\Microsoft Security Client
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-07-11 22:53 . 2012-04-17 10:20 426184 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-07-11 22:53 . 2011-05-16 11:34 70344 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-06-13 13:19 . 2005-08-16 10:18 1866112 —-a-w- c:\windows\system32\win32k.sys
2012-06-05 15:50 . 2010-10-01 22:16 1372672 —-a-w- c:\windows\system32\msxml6.dll
2012-06-05 15:50 . 2005-08-16 10:18 1172480 —-a-w- c:\windows\system32\msxml3.dll
2012-06-04 04:32 . 2005-08-16 10:18 152576 —-a-w- c:\windows\system32\schannel.dll
2012-06-02 19:19 . 2009-08-07 00:24 22040 —-a-w- c:\windows\system32\wucltui.dll.mui
2012-06-02 19:19 . 2009-08-07 00:24 15384 —-a-w- c:\windows\system32\wuaucpl.cpl.mui
2012-06-02 19:19 . 2005-08-16 10:40 329240 —-a-w- c:\windows\system32\wucltui.dll
2012-06-02 19:19 . 2005-08-16 10:40 210968 —-a-w- c:\windows\system32\wuweb.dll
2012-06-02 19:19 . 2005-08-16 10:40 219160 —-a-w- c:\windows\system32\wuaucpl.cpl
2012-06-02 19:19 . 2009-08-07 00:24 45080 —-a-w- c:\windows\system32\wups2.dll
2012-06-02 19:19 . 2009-08-07 00:24 15384 —-a-w- c:\windows\system32\wuapi.dll.mui
2012-06-02 19:19 . 2005-08-16 10:40 53784 —-a-w- c:\windows\system32\wuauclt.exe
2012-06-02 19:19 . 2005-08-16 10:40 35864 —-a-w- c:\windows\system32\wups.dll
2012-06-02 19:19 . 2005-08-16 10:18 97304 —-a-w- c:\windows\system32\cdm.dll
2012-06-02 19:19 . 2009-08-07 00:24 17944 —-a-w- c:\windows\system32\wuaueng.dll.mui
2012-06-02 19:19 . 2005-08-16 10:40 577048 —-a-w- c:\windows\system32\wuapi.dll
2012-06-02 19:19 . 2005-08-16 10:40 1933848 —-a-w- c:\windows\system32\wuaueng.dll
2012-06-02 19:18 . 2010-10-02 02:57 275696 —-a-w- c:\windows\system32\mucltui.dll
2012-06-02 19:18 . 2010-10-02 02:57 214256 —-a-w- c:\windows\system32\muweb.dll
2012-06-02 19:18 . 2010-10-02 02:57 17136 —-a-w- c:\windows\system32\mucltui.dll.mui
2012-05-31 13:22 . 2005-08-16 10:18 599040 —-a-w- c:\windows\system32\crypt32.dll
2012-05-16 15:08 . 2005-08-16 10:18 916992 —-a-w- c:\windows\system32\wininet.dll
2012-05-11 14:42 . 2005-08-16 10:18 43520 —-a-w- c:\windows\system32\licmgr10.dll
2012-05-11 14:42 . 2005-08-16 10:18 1469440 ——w- c:\windows\system32\inetcpl.cpl
2012-05-11 11:38 . 2005-08-16 10:18 385024 —-a-w- c:\windows\system32\html.iec
2012-05-04 13:16 . 2005-08-16 10:18 2148352 —-a-w- c:\windows\system32\ntoskrnl.exe
2012-05-04 12:32 . 2004-08-04 04:59 2026496 —-a-w- c:\windows\system32\ntkrnlpa.exe
2012-05-02 13:46 . 2005-08-16 10:37 139656 —-a-w- c:\windows\system32\drivers\rdpwd.sys
2010-03-11 04:01 . 2010-03-11 04:01 124272 —-a-w- c:\program files\mozilla firefox\plugins\CCMSDK.dll
2010-03-11 04:40 . 2010-03-11 04:40 13168 —-a-w- c:\program files\mozilla firefox\plugins\cgpcfg.dll
2010-03-11 04:02 . 2010-03-11 04:02 70512 —-a-w- c:\program files\mozilla firefox\plugins\CgpCore.dll
2010-03-11 04:01 . 2010-03-11 04:01 91504 —-a-w- c:\program files\mozilla firefox\plugins\confmgr.dll
2010-03-11 04:01 . 2010-03-11 04:01 22384 —-a-w- c:\program files\mozilla firefox\plugins\ctxlogging.dll
2010-03-11 04:00 . 2010-03-11 04:00 255344 —-a-w- c:\program files\mozilla firefox\plugins\ctxmui.dll
2010-03-11 04:01 . 2010-03-11 04:01 31088 —-a-w- c:\program files\mozilla firefox\plugins\icafile.dll
2010-03-11 04:01 . 2010-03-11 04:01 40304 —-a-w- c:\program files\mozilla firefox\plugins\icalogon.dll
2009-10-05 17:49 . 2009-10-05 17:49 652640 —-a-w- c:\program files\mozilla firefox\plugins\sslsdk_b.dll
2010-03-11 04:02 . 2010-03-11 04:02 23920 —-a-w- c:\program files\mozilla firefox\plugins\TcpPServ.dll
2012-07-20 10:44 . 2011-05-02 21:54 136672 —-a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-29 67584]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 339968]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2005-06-17 139264]
"ATIPTA"="c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2005-08-06 344064]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 53248]
"RealTray"="c:\program files\Real\RealPlayer\RealPlay.exe" [2005-12-19 26112]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-12-06 127035]
"ISUSPM Startup"="c:\program files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 249856]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 81920]
"MimBoot"="c:\progra~1\MUSICM~1\MUSICM~3\mimboot.exe" [2005-09-09 8192]
"MSKDetectorExe"="c:\program files\McAfee\SpamKiller\MSKDetct.exe" [2005-07-13 1117184]
"ConnectionCenter"="c:\program files\Citrix\ICA Client\concentr.exe" [2010-03-11 300400]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2011-10-24 421888]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-18 254696]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 931200]
.
c:\documents and settings\Kevin\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Content Manager Assistant for PlayStation®.lnk - c:\program files\Sony\Content Manager Assistant\CMA.exe [2012-1-26 2520504]
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2005-12-19 24576]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
.
R1 ctxusbm;Citrix USB Monitor Driver;c:\windows\system32\drivers\ctxusbm.sys [10/5/2009 10:08 AM 65584]
R1 MpKsladdc328d;MpKsladdc328d;c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{BC5D45CB-D8D6-4DD0-AD02-6796760E061B}\MpKsladdc328d.sys [7/22/2012 1:38 AM 29904]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/17/2012 6:20 AM 250056]
S3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files\Mozilla Maintenance Service\maintenanceservice.exe [4/25/2012 7:46 AM 113120]
S3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\drivers\wdcsam.sys [2/13/2009 3:02 PM 11520]
.
— Other Services/Drivers In Memory —
.
*NewlyCreated* - MPKSLADDC328D
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
.
2012-07-22 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-17 22:53]
.
2012-07-22 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 22:57]
.
2012-07-22 c:\windows\Tasks\Microsoft Antimalware Scheduled Scan.job
- c:\program files\Microsoft Security Client\MpCmdRun.exe [2012-03-26 21:03]
.
.
——- Supplementary Scan ——-
.
uStart Page = hxxp://www.dell4me.com/myway
Trusted Zone: musicmatch.com\online
TCP: DhcpNameServer = [removed] [removed]
FF - ProfilePath - c:\documents and settings\Kevin\Application Data\Mozilla\Firefox\Profiles\mvuvldgi.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yankees.com/
FF - prefs.js: network.proxy.type - 0
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-Apple - c:\documents and settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll
HKU-Default-Run-Apple - c:\documents and settings\Missy\Local Settings\Application Data\Apple Computer\Apple\rtfzrvfnz.dll
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2012-07-22 07:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes …
.
scanning hidden autostart entries …
.
scanning hidden files …
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
Completion time: 2012-07-22 07:19:29
ComboFix-quarantined-files.txt 2012-07-22 11:19
.
Pre-Run: 42,415,812,608 bytes free
Post-Run: 42,381,115,392 bytes free
.
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
.
- - End Of File - - 38382EB380F25AFCAD75D503E831D4B4
Ok….I should have said it before…. Can you look for ComboFix.txt inside of C:\Qoobox\ If it is there please post it. I am just trying to verify something. :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI